Inspiration
Everyone has been told how to spot a scam: check the sender, don't tap the link, never share a code. Then a message arrives while you're busy, it sounds urgent, and the advice is nowhere to be found. Knowing the rules isn't the same as having the instinct. "Chat, is this real?" is the question we want people to be able to answer on their own. So we built a safe place to practise on the real thing, again and again, until spotting a scam becomes a reflex.
What it does
chatisthisreal puts a practice phone in your browser. Scam texts, phishing emails and live AI voice calls arrive on it the way they would on your own phone, and you react as you normally would: tap the link, inspect the sender, report it, mark it safe, or pick up and talk.
- Three channels: texts and emails to judge, and a live voice caller you can answer, talk to and hang up on, with captions.
- Not everything is a scam: close to half of the practice texts and emails are genuine, so "report everything" doesn't work.
- Debriefs that teach: after each scenario you see the red flags you caught or missed, highlighted in the message itself.
- It adapts to you: chatisthisreal tracks which scam types and tactics fool you (say, authority combined with urgency) and writes the next scenario to train exactly that. Difficulty steps up as you get things right and eases off after misses.
- Missions and badges: short missions mix texts, emails and calls, with rewards for finishing them.
Nothing real is ever at risk: no real messages, links or calls leave the app.
How we built it
- Frontend: React 19, TypeScript and Vite for the phone simulator, debriefs and progress views. Texts stream in over server-sent events.
- Backend: one Express API on Node.js, with Firebase Authentication verifying every request.
- Scam library: an offline Python pipeline curates about 600 real phishing emails, spam texts and scam-call patterns from public Kaggle and UCI datasets. Every scenario is grounded in it.
- Gemini writes personalised emails and call scripts from your profile, your weak spots and 2–3 matching library examples.
- ElevenLabs runs the live call as a voice agent, and its post-call analysis tells us what you gave away (codes, card numbers, personal details).
- TigerData stores every tap and decision in a TimescaleDB hypertable and turns it into metrics over time.
- Snowflake compares pseudonymous aggregates across trainees to find which tactic combinations work on you, optionally with Cortex wording the summary.
Challenges we ran into
- "Report" was always the right answer. Our first scenarios were all scams, so the winning strategy was to report everything without reading. We added genuine messages, built from real legitimate emails in the same datasets, so you have to tell real from fake.
- Keeping generated content trustworthy. Every red flag Gemini names must quote the message word for word, or the debrief can't highlight it, and no real brand may appear. Our brand filter had bugs of its own: the rule for UPS was catching "pop-ups" and "sign-ups".
- Four people, one loop. We started with a separate comms service and API talking over an internal token, and early merges had to be reverted and reapplied. We folded everything into one server with one auth path, then wrote the shared contracts down before building the adaptive loop.
- Live calls have many ways to go wrong. A call can ring unanswered, get stuck connecting, or be abandoned mid-ring. Each case needed the right outcome so it never counts as a miss you didn't have.
Accomplishments that we're proud of
- The whole loop works end to end: what you do in one scenario changes the next one, and the debrief shows you what changed.
- You can hold a real spoken conversation with a scam caller and get scored on what you gave away.
- No hand-written scams: the practice path and the generated scenarios all come from real-world examples.
- Honest labels: "Written by Gemini" or "Analysed in Snowflake" appear only when that service really produced the result. Every optional service has a fallback, so the app keeps working without it.
- Privacy by design: Snowflake only receives a keyed hash of the user id plus aggregate counts and rates.
What we learned
- A training tool teaches whatever its scoring rewards. If every message is a scam, people learn to report, not to read.
- Model output is a draft. Checking it against the exact text the user sees, with a fallback behind it, is what makes it usable.
- Grounding Gemini in real examples gave us scenarios that read like the real thing, and saved us from writing scams by hand.
- Agreeing the contract first let four people build one loop in parallel.
What's next for chatisthisreal
- Personalized texts written per person, the way emails and calls are today.
- Genuine calls, so hanging up isn't always the right answer.
- Scams in more languages and from more regions.
- Shared practice for families and workplaces, so people can train together.
Built With
- claude-code
- css
- elevenlabs
- express.js
- firebase
- gemini
- html5
- kaggle
- motion
- node.js
- pandas
- postgresql
- python
- react
- react-router
- server-sent-events
- snowflake
- snowflake-cortex
- tailwindcss
- tigerdata
- timescaledb
- typescript
- vite
- webrtc
- zod

Log in or sign up for Devpost to join the conversation.